Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Link to portal for reporting security vulnerabilities in Microsoft packages #8655

Closed
jcjiang opened this issue Jun 23, 2021 · 0 comments
Closed

Comments

@jcjiang
Copy link

jcjiang commented Jun 23, 2021

Is your feature request related to a problem? Please describe.

Currently, the only option for users seeking to report a security vulnerability they found in a hosted package is to submit the report under:
image

This is an issue because

  • these reports enter with the category of 'this package has malicious code,' which is a different problem
  • comes in as email to a list, can be lost
  • case does not undergo formal evaluation and severity rating
  • no Microsoft CVE attached
  • not updated on the regular security monthly release schedule

Describe the solution you'd like

Add an option to the dropdown:
image

Selecting the option results in the following text:
image

The hyperlink leads to the following form:

image

Additional context

This feature came from conversation with VS security and MSRC PMs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants